Information
This policy setting determines the type of PIN or password this is required on a system.
The recommended state for this setting is: Password or Alphanumeric PIN required
Note: This policy only applies if the DevicePasswordEnabled policy is set to 1 This is a pre-requisite for
Alphanumeric Device Password Required
in the settings catalog.
This is a pre-requisite for
Min Device Password Complex Characters
, which enforces a more complex local user and Microsoft account passwords.
Note: This setting has no impact on Entra ID accounts.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Password or Alphanumeric PIN required :
Device Lock\Device Password Enabled: Alphanumeric Device Password Required
Impact:
If an organization is using Windows Hello for Business then the Device Lock password settings can impact PIN polices if those policies are not first defined elsewhere. Windows will follow the Windows Hello for Business policies for PINs if this key exists: HKLM\SOFTWARE\Microsoft\Policies\PassportForWork\<Tenant-ID>\Device\Policies Otherwise, it will follow Device Lock policies.
This benchmark recommends configuring Device Lock policies for Local User accounts and Windows Hello for Business policies for PINs.